Cisco Talos has identified a Chinese-speaking intrusion actor called UAT-10147. The group is targeting vulnerable Windows and Linux web servers worldwide. Talos said the actor uses artificial intelligence to automate several stages of its attacks. These include reconnaissance, exploitation, payload generation, validation, and persistence.
The activity emerged in early 2026 and led to threats for 170,000 servers worldwide. UAT-10147 appears financially motivated and conducts SEO fraud alongside data theft. Its targets span government, education, media, technology, and gaming sectors.
AI Helps Scale UAT-10147 Intrusions
The newly identified threat actor's use of AI goes beyond basic scripting assistance. The threat intelligence team, Talos, observed iterative exploit refinement and adaptive troubleshooting during intrusions. It also found automated post-exploitation and exploit validation workflows.
The Chinese-speaking cybercrime group used AI-generated operational playbooks and automation scripts. These tools helped refine attacks and resolve problems during operations.
It also used several open-source offensive tools, including Metasploit, ysoserial, PentestGPT, and DeepAudit. The actor combined them with privilege escalation exploits.
As per the revelations of Talos, this activity signals a shift toward semi-autonomous offensive operations. The approach can reduce the expertise needed for complex post-compromise activity.
Talos Tracked About 170,000 Targets
The scale of the campaign is another major concern. Talos found a target list containing about 170,000 URLs. The list was stored on a command-and-control server's open directory. The actor divided the list into 17 files. Each file contained roughly 10,000 URLs. Talos found affected systems across the United States, India, the United Kingdom, Germany, the Netherlands, and others. Among these countries, the United States listed 52,496 targets while India recorded 8,923 targets.
The campaign primarily targets internet-exposed web servers. The threat actor exploits publicly disclosed vulnerabilities to gain initial access. It then deploys malware or web shells for further operations.
On Windows systems, the actor used scripts, privilege escalation tools, and scheduled tasks. It also modified Defender exclusions to dodge security scans. On Linux systems, the threat actor deployed web shells after gaining remote code execution. It then used known privilege escalation vulnerabilities to obtain higher privileges.
SPECTRE Adds Persistence and Evasion
Talos also tracked SPECTRE, a custom cross-platform backdoor used by UAT-10147. The malware operates on both Windows and Linux systems. SPECTRE supports command-and-control communications, process injection, credential theft, and anti-analysis features. Its Windows version also uses BYOVD techniques for EDR evasion.
On Linux, the actor deployed a kernel rootkit called Specter. Talos found signs that AI-assisted development may have contributed to parts of the malware. The findings show how AI can strengthen existing cybercrime operations. The threat actor combines automated attack workflows with custom malware and established offensive tools.
As remediation, organizations should prioritize patching and monitor unusual web shells, scripts, and privileged activity. SecureITWorld is a leading publication for cybersecurity insights, news, and advancement. Visit our site and start understanding the cybersecurity space thoroughly.
Also Read:
The Future of Cybersecurity: What to Expect?
Managed Security Services (MSS) vs. In-House Cybersecurity: Which Model Suits Your Business






